Sponsored: Munich Re
A.I. Beyond the Boardroom: Turning Innovation into Resilience

Across industries, organizations are rapidly embedding artificial intelligence (A.I.) into customer service, operations, software development, risk analysis, and decision-making. The result has been remarkable in productivity and efficiency. But as A.I. adoption accelerates, the associated risks are evolving just as quickly. Bryan Barrett, Regional Underwriting Manager, Cyber and Technology E&O at Munich Re Specialty – North America, indicates that many organizations are moving faster with A.I. deployment than they are with governance, oversight, and security.
“Companies are understandably eager to innovate and capitalize on the benefits of A.I.,” says Barrett. “The challenge is that oversight, tracking, and compliance often lag behind implementation, creating potential operational, financial, and legal exposures.”
The A.I. Governance Gap

Bryan Barrett, Regional Underwriting Manager, Cyber and Technology E&O, Munich Re Specialty – North America
As A.I. moves deeper into daily business operations, organizations face a growing governance challenge.
“The most common mistake organizations make is assuming A.I. is simply another software application that can be plugged into the environment,” says Barrett. “Traditional software operates by a set of rules with predictable outcomes. A.I. does not, which makes understanding and managing risk significantly more complex.”
Recent research suggests the A.I. governance gap is actually widening. IBM’s 2026 Cost of a Data Breach Report found that 68% of breached organizations lacked formal A.I. governance policies, while another 33% reported their policies were still under development. This reinforces the idea that A.I. adoption continues to outpace organizational oversight, creating growing security, operational, compliance, and reputational risks.
IBM’s report also found that 92% of organizations experiencing an A.I.-related breach lacked proper A.I. access controls, highlighting how basic governance and identity management continue to lag behind adoption. At the same time, security incidents involving shadow A.I., the unauthorized use of A.I. tools or applications by employees without approval or oversight of the information technology (IT) department, more than doubled year over year, rising from 20% to 43% of organizations surveyed. Those incidents resulted in average breach costs of $5.39 million and were frequently associated with data loss, operational disruption, reputational damage, and even regulatory fines.
Attackers Are Leveraging A.I., Too
While A.I. is helping organizations innovate, cybercriminals are also using the technology to enhance their capabilities.
“A significant number of organizations have seen an uptick in cyberattacks that leverage A.I.,” says Barrett. “A.I. allows threat actors to attack faster, more quietly, and more efficiently than ever before.”
Attackers are increasingly using A.I. to automate credential-stuffing campaigns, accelerate brute-force attacks, create convincing phishing messages, and generate sophisticated deepfakes. These tools lower the barrier to entry for cybercrime while increasing the scale and effectiveness of attacks.
Research suggests attackers are accelerating A.I. adoption faster than defenders. IBM’s 2026 report found that more than one in four organizations experienced an A.I.-driven attack, representing a 56% increase over the previous year. Deepfake impersonation attacks accounted for the largest share of A.I.-enabled incidents at 45%, followed by A.I.-generated malware and A.I.-powered phishing campaigns. Researchers found that an A.I.-driven cyberattack costs an average of $1 million more compared with breaches caused by traditional attacks.
The 2026 NetDiligence Cyber Claims Study highlights similar concerns, noting that artificial intelligence is accelerating the speed and scale of attacks by helping threat actors automate reconnaissance, create more convincing social engineering content, and lower the technical barriers to cybercrime. Contributors also point to the growing use of deepfakes and synthetic media to impersonate executives, employees, vendors, and other trusted parties, increasing the effectiveness of fraud and business email compromise schemes. As A.I. continues to compress the time between attack planning and execution, organizations may face a greater volume of incidents and increasingly sophisticated threats.
Beyond phishing and impersonation, A.I. systems themselves are becoming attack targets.
According to Barrett, cybercriminals are increasingly targeting A.I. models through techniques such as data poisoning, where malicious data is introduced to influence model outputs and behavior. “These attacks can result in organizations having to conduct extensive forensic reviews and retraining exercises to restore confidence in their systems,” he explains.
Balancing Innovation with Risk Management
Organizations often view A.I. primarily through the lens of efficiency, automation, and competitive advantage. Those benefits are real. However, successful A.I. adoption requires a balanced approach that incorporates governance and cybersecurity from the outset.
“Risk management is essential to the foundation of A.I. adoption,” says Barrett. “Leaders need to take a cautious and disciplined approach when developing and implementing A.I. systems within their organizations.”
A strong A.I. governance framework should establish clear policies around deployment, usage, access management, vendor oversight, and data handling. Just as importantly, organizations should define accountability for A.I.-related decisions and ensure ongoing monitoring as technologies evolve.
Employee education also remains critical. Many A.I.-enabled attacks continue to exploit human behavior, particularly through phishing, social engineering, and fraud schemes that are appearing even more authentic than ever before with the use of these tools.
Looking Ahead: A More Proactive Security Model
One of the most significant shifts occurring in cybersecurity is the move from reactive defense to proactive resilience.
“Organizations can no longer afford to simply react to A.I.-related attacks once they occur,” says Barrett. “The threats are becoming too sophisticated and too fast.”
Instead, he recommends that organizations focus on several core priorities:
- Adopting zero-trust security principles, based on access being granted only after verification.
- Investing in tools capable of identifying anomalous and A.I.-driven behaviors.
- Implementing robust A.I. governance programs.
- Providing ongoing employee education on advanced phishing and social engineering threats.
The financial stakes continue to rise. IBM’s 2026 report found the global average breach cost increased 12% to a record $4.99 million, while the average breach costs in the United States climbed to $11.5 million, more than double the global average.
At the same time, the report demonstrates that A.I. can be an important defensive advantage when implemented responsibly. Organizations that extensively used A.I. and automation within security operations reduced average breach costs by $1.93 million and shortened breach identification and containment times by 65 days compared with organizations that did not use those technologies. The bad news is only 36% of organizations reported extensive use of A.I. and automation across the security lifecycle.
Helping Organizations Adopt A.I. with Confidence
As organizations navigate this rapidly evolving risk landscape, many are looking for expert guidance. To address this need, Munich Re Specialty – North America has partnered with CyRisk to develop a new A.I. module for the Reflex™ Cyber Risk Management program. The new A.I. module is a complimentary A.I. risk management consulting service available to policyholders designed to help organizations understand, evaluate, and manage A.I.-related risks before they become costly incidents.
“Reflex’s A.I. services are designed to help organizations adopt A.I. with confidence,” said Barrett. “The program focuses on A.I. strategy, governance, security, and engineering practices so organizations can realize productivity gains while mitigating new security, privacy, and regulatory exposures.”
For veterans of cyber risk management, the conversation around A.I. risk often mirrors earlier discussions surrounding cloud adoption, digital transformation, and cybersecurity modernization. Organizations that approach innovation without governance often discover that risk accumulates faster than expected and can be costly. Those that integrate security, oversight, and resilience into their strategy from the beginning are better positioned to unlock A.I.’s benefits while managing the risk.
Learn how Munich Re Specialty – North America and its partners can help identify where A.I. exposure exists across your organization, and offer actionable guidance: https://www.munichre.com/specialty/north-america/en/solutions/cyber/reflex.html.
![]()
This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with Munich Re Specialty. The editorial staff of Risk & Insurance had no role in its preparation.

